Domain Migration of Windows server 2003 to 2008 R2 Active Directory


  I currently have two server running Windows Server 2003 that I have started managing.

1. FileServ (File Server, DHCP, DNS, Active Directory)
2. PDC (DNS, Active Directory)

Recently I have started migrating servers into vmware using their p2v standalone converter, however I have read several articles that converting active directory servers is not supported. What is the best method of settings up two Windows Server 2008 r2 servers and migrating my 2003 active directory to the 2008 servers? I currently have two Windows Server 2008 VM's running:

1. DC01
2. DC02

I have found the following links on how to perform this migration, however there is not a lot of comments saying if the migration was successful or not. Here are the links:


Any direction in the best method to turn the two Server 2008 servers into my main AD, DNS servers would be a big help. Then I will simply P2V my fileserver after demoting and removing AD, DNS, and DHCP on my 2003 servers.
Jonathan CarpenterNetwork AdministratorAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Parrish ChamberlainSupportability and Transition ManagerCommented:
Firstly are you using Microsoft Virtual Machine Manager?  Download it fromHere . Notes can be found here .

To create a virtual machine from a physical server


On the Actions pane in any view in the Virtual Machine Manager Administrator Console, click Convert physical server to open the Convert Physical Server Wizard.


On the Select Source page, configure the following options:
Computer name. Type the computer name of the physical server that you want to use as the source   for the new virtual machine, or click Browse to locate the server.
User name. Type the name of a user account that has local Administrator rights and permissions on the source machine.
Password. Type the user password.
Domain. If the domain name field is not already pre-populated, type the name of the domain.


On the Virtual Machine Identity page, configure the following options:
Virtual machine name. Accept the pre-populated virtual machine name, which is the same computer name as the name of the source physical server. Alternatively, you can type a different name.
Owner. Accept the pre-populated value, DomainName\Username, to identify yourself as the owner of the new virtual machine. Alternatively, click Select to specify a different user or group as the owner. The account specified must be an Active Directory account.
Description (optional).Type a description for the new virtual machine.


On the Gather Information page, click Gather System Information to begin a SURVEY of the source machine that lists its hardware and software and identifies any missing components that are required for the P2V conversion. The wizard installs software on the source machine to gather the information but removes this software when the conversion is complete.

I have used this tool successfully, once converted you can upload to your Virtual Architecture
Jonathan CarpenterNetwork AdministratorAuthor Commented:
Hello Parrish,

  Thank you for the information, however I am using VMware vCenter for all of my virtualization. Virtualizing P2V is completed through the vmware standalone converter and it works great for me however P2V conversion of AD servers is not supported (resulting in a basically dead AD server).

  I am needing a set of solid instructions on the proper steps to migrate AD from 2003 to 2008 that has been used by others and proven to work. I have already setup two servers running Server 2008 R2 in my virtual environment that I will use for my AD Domain Controllers. The previous two links I provided in the initial question were steps to accomplish this, but there was limited feed back on how it worked.

  At this time all I want to do is follow a solid plan to prep the Server 2003 server for AD migration, migrate all AD functions to my 2008 servers, then demote my 2003 servers, and of course have functioning AD for all of my USERS & Computers without downtime. After this is done my Server 2003 file server will be able to P2V and my virtualization and AD migrations will be completed.
Sumit GuptaSystem and Virtualization EngineerCommented:

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
To migrate to 2008 R2
You already have setup 2008 R2 VMs, right ?
Do not ever enable VM snapshots for these VMs.

Ensure that you logged on to 2003 server with account having domain admins, enterprise admins and schema admins membership
Then on 2003 Domain controllers where you have all FSMO running insert 2008 R2 dvd and browse to support\adprep folder
Run below commands if your 2003 is 32-bit
adprep32 /forestprep
adprep32 /domainprep
adprep32 /domainprep /gpprep
adprep32 /rodcprep    --- if you want to run RODC in domain in future


Run below commands if your 2003 is 64-bit
adprep /forestprep
adprep /domainprep
adprep /domainprep /gpprep
adprep /rodcprep    --- if you want to run RODC in domain in future

Now join 2008 R2 server to domain and run dcpromo on that server to promote it to ADC
Once you deployed ADC on both 2008 R2 machines ensure that name resolution \ ad replication \ Sysvol replication is running fine
Ensure below
All dns zones must be populated on both servers
all servers NS records \ CNAME records \ Host (A) records \ all zones are populated on both servers
Run net share on both servers to check if netlogon and Sysvol is shared out
Point both servers to itself own IP (Not for name resolution and keep another server as alternate DNS
Set your Internet DNS forwarders on 2008 r2 servers
Transfer FSMO roles from 2003 to 2008 r2 servers
Then point all of your client computers and servers \ dhcp scopes to 2008 R2 servers and shutdown 2003 servers for time being
Check if 2008 r2 Dcs are able to authenticate all client computers and servers
Run Netdom Query fsmo on all domain controllers and ensure that its output is same across all domain controllers
Once all testing is over, you can simply demote 2003 Domain controllers

Last things to say:
Never use physical to virtual conversion for DCs if you have more than one DC, it works fine if you have only single DC in domain.
Never use \ take domain controller snapshots
Configure AD time sync on 2008 R2 domain controllers -

Remove DC vm integration with physical host in VM tools settings
SandeshdubeySenior Server EngineerCommented:
Configuring DC either from clone/snapshot/image is not recommended.I recommend proceeding like that:
•Promote a new VM as a DC and make it a DNS and GC server
•Transfer all FSMO roles holder by the DC to demote to this VM
•Check that all is okay with AD replication using dcdiag.exe and then demote the old DCs
Note that it is recommended to have at least two DC / DNS / GC servers per domain.

Adding first Windows Server 2008 R2 Domain Controller within Windows 2003 network

Hope this helps
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Server 2008

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.